Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

openSUSE: 2019:2540-1 Important: Squid Remote Code Execution Fix

opensuse
Calendar Grey November 21, 2019
Dist Opensuse Esm H88
Critical openSUSE Security Patch for apache tackling 15 vulnerabilities, covering the spectrum from arbitrary code execution to SQL injection threats.
An update that fixes 12 vulnerabilities is now available.

Description

This update for squid to version 4.9 fixes the following issues:

Security issues fixed:

- CVE-2019-13345: Fixed multiple cross-site scripting vulnerabilities in

cachemgr.cgi (bsc#1140738).

- CVE-2019-12526: Fixed potential remote code execution during URN

processing (bsc#1156326).

- CVE-2019-12523,CVE-2019-18676: Fixed multiple improper validations in

URI processing (bsc#1156329).

- CVE-2019-18677: Fixed Cross-Site Request Forgery in HTTP Request

processing (bsc#1156328).

- CVE-2019-18678: Fixed incorrect message parsing which could have led to

HTTP request splitting issue (bsc#1156323).

- CVE-2019-18679: Fixed information disclosure when processing HTTP Digest

Authentication (bsc#1156324).

Other issues addressed:

* Fixed DNS failures when peer name was configured with any upper case

characters * Fixed several rock cache_dir corruption issues

This update was imported from the SUSE:SLE-15:Update update...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.0:

zypper in -t patch openSUSE-2019-2540=1

Package List

- openSUSE Leap 15.0 (x86_64):

squid-4.9-lp150.13.1

squid-debuginfo-4.9-lp150.13.1

squid-debugsource-4.9-lp150.13.1

References

https://www.suse.com/security/cve/CVE-2019-12523.html

https://www.suse.com/security/cve/CVE-2019-12525.html

https://www.suse.com/security/cve/CVE-2019-12526.html

https://www.suse.com/security/cve/CVE-2019-12527.html

https://www.suse.com/security/cve/CVE-2019-12529.html

https://www.suse.com/security/cve/CVE-2019-12854.html

https://www.suse.com/security/cve/CVE-2019-13345.html

https://www.suse.com/security/cve/CVE-2019-18676.html

https://www.suse.com/security/cve/CVE-2019-18677.html

https://www.suse.com/security/cve/CVE-2019-18678.html

https://www.suse.com/security/cve/CVE-2019-18679.html

https://www.suse.com/security/cve/CVE-2019-3688.html

https://bugzilla.suse.com/1133089

https://bugzilla.suse.com/1140738

https://bugzilla.suse.com/1141329

https://bugzilla.suse.com/1141330

https://bugzilla.suse.com/1141332

https://bugzilla.suse.com/1141442

https://bugzilla.suse.com/1156323

https://bugzilla.suse.com/1156324

https://bugzilla.suse.com/1156326

https://bugzilla.suse.com/1156328

https://bugzilla.suse.com/1156329

--...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2019:2540-1
Rating: important
Affected Products: openSUSE Leap 15.0

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here